{"id":"CVE-2026-105753","title":"vLLM is an inference and serving engine for large language models","summary":"vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, w…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-617"],"vendor":"vllm-project","product":"vllm","affected":["vllm < 0.28.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T23:17:01.867","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105753","references":[{"url":"https://github.com/vllm-project/vllm/commit/396204230423b7cc6798300926b8fa30190d26a9","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/pull/46747","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/pull/51897","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/releases/tag/v0.28.0","label":"security-advisories@github.com"},{"url":"https://github.com/vllm-project/vllm/security/advisories/GHSA-ph3r-5jfg-f84f","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-ph3r-5jfg-f84f"}],"tags":["nvd","cve.org","ghsa","pip"],"ingestedAt":"2026-10-05T23:36:21.155Z","aliases":["GHSA-ph3r-5jfg-f84f"],"ecosystem":"pip","patched":["vllm 0.28.0"],"slug":"CVE-2026-105753","body":"## Overview\n\nvLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, while the engine receiver cache never receives the payload if that request is rejected. A later request reusing the same media hash causes MultiModalProcessorSenderCache to send no payload and MultiModalReceiverCache to reach an assertion with the message \"Expected a cached item,\" producing a shared-service availability failure. This issue is fixed in version 0.28.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-105753)\n\nAffected packages:\n\n- `vllm < 0.28.0`\n\nPatched in:\n\n- `vllm 0.28.0`\n\nSource: https://github.com/advisories/GHSA-ph3r-5jfg-f84f","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}